CVE-2020-24584
Summary
| CVE | CVE-2020-24584 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-01 13:15:00 UTC |
| Updated | 2023-11-07 03:20:00 UTC |
| Description | An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level directories of the filesystem cache had the system's standard umask rather than 0o077. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 31 Update: python-django-2.2.16-1.fc31 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 32 Update: python-django-3.0.10-3.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 31 Update: python-django-2.2.16-1.fc31 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Archive of security issues | Django documentation | Django |
MISC |
docs.djangoproject.com |
Vendor Advisory |
| oss-security - Django Security Releases for CVE-2020-24583 & CVE-2020-24584:
permissions on intermediate-level directories on Python 3.7+ |
MISC |
www.openwall.com |
Mailing List, Patch, Third Party Advisory |
| [SECURITY] Fedora 32 Update: python-django-3.0.10-3.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 33 Update: python-django-3.0.10-3.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Google Groups |
MISC |
groups.google.com |
Third Party Advisory |
| Django security releases issued: 3.1.1, 3.0.10 and 2.2.16 | Weblog | Django |
MISC |
www.djangoproject.com |
Vendor Advisory |
| [SECURITY] Fedora 33 Update: python-django-3.0.10-3.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| USN-4479-1: Django vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| Google Groups |
MISC |
groups.google.com |
Third Party Advisory |
| September 2020 Django Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| Oracle Critical Patch Update Advisory - January 2021 |
MISC |
www.oracle.com |
|
| Google Groups |
|
groups.google.com |
|
| Google Groups |
|
groups.google.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 181172 Debian Security Update for python-django (DLA 3164-1)
- 296071 Oracle Solaris 11.4 Support Repository Update (SRU) 27.82.1 Missing (CPUOCT2020)
- 500579 Alpine Linux Security Update for py3-django
- 501674 Alpine Linux Security Update for py3-django
- 690730 Free Berkeley Software Distribution (FreeBSD) Security Update for django (002432c8-ef6a-11ea-ba8f-08002728f74c)
- 982909 Python (pip) Security Update for django (GHSA-fr28-569j-53c4)